Skip to content
Threat Feed

Product

ConnectWise ScreenConnect

4 briefs RSS
high advisory

ClearFake, ACR Stealer, and GraphRunner Emerge as Significant Threats

The Red Canary Intelligence Insights report for May 2026 highlights the rise of ClearFake, ACR Stealer, and GraphRunner, with ClearFake using JavaScript injection to deliver malware like ACR Stealer, and GraphRunner being abused for reconnaissance and data exfiltration via the Microsoft Graph API.

Entra ID +6 credential-theft malware oauth
2r 4t 2i
high advisory

Zoom-themed Phishing Campaign Delivering ConnectWise ScreenConnect

A phishing campaign impersonates Zoom to trick users into downloading and installing ConnectWise ScreenConnect, a legitimate remote monitoring and management tool, allowing attackers to gain persistent remote access, harvest credentials, and deploy secondary malware such as ransomware.

Zoom +2 phishing remote_access social_engineering screenconnect
2r 5t 4i
high advisory

ScreenConnect Server Spawning Suspicious Processes

The ScreenConnect server is spawning suspicious processes such as cmd.exe and powershell.exe, potentially indicating exploitation or web shell activity leading to unauthorized access and control over the system.

ConnectWise ScreenConnect webshell screenconnect initial-access
2r 4t
medium advisory

Remote Management Software Launch After MSI Install

Attackers are leveraging MSI installers to deploy remote management software (RMM) such as ScreenConnect, Syncro, and VNC, potentially indicating unauthorized access and control over compromised systems.

ConnectWise ScreenConnect +3 remote-access rmm msi command-and-control
3r